Designated verifier signature without random oracles
Yongjian Liao, Chenjun Jia · 2008
There are only two possible signers in designated verifier signature(DVS) scheme, thus anyone else can not know who is the real signer according to signature/message pairs. Lipmaa et al. discovered delegatability attack on almost all existing designated verifier signature. In fact all DVS scheme based on pairings are delegatable. In this paper we first formally define DVS in the standard model. Then we present an efficient DVS without random oracles from bilinear pairings. Finally, we construct a constant-size mult-DVS scheme based on foregoing scheme.